Identity and Access management; IAM Mainframe Security Administration Sr Manager; RACF exp. re
Listed on 2025-12-20
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Systems Administrator
Job Description
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day. Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank's Information Security strategy and policy, manages the Information Security program, identifies, and addresses vulnerabilities and operates global security operations centers that monitor, detect, and respond to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context.
IAM addresses the mission‑critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements.
The Mainframe Security Administration Manager leads a team of analysts responsible for managing secure access to mainframe systems. This role requires a blend of technical acumen in mainframe security mechanisms (RACF, ACF2, Top Secret), strong governance expertise including knowledge of industry standards, and leadership of team members as a key stakeholder within Information Security and the broader IT organization. This candidate will oversee access provisioning processes, ensure compliance with our Identity and Access Management policies, and standards frameworks for critical applications and drive continuous improvement in administering security and overseeing operation processes.
This role is critical to maintaining the integrity, confidentiality, and availability of mainframe resources across the enterprise supporting development, implementation, communication, monitoring and maintenance of the information security policies and procedures. This candidate will be an important contributor within the team responsible for the development and implementation of security standards, procedures, and guidelines. You will provide subject matter expertise and support to internal customers, IT management, and staff in assessing risk and the implementation of appropriate security procedures and products.
Escalate process issues and effectively communicate these risks and all other types of risk to management and key stakeholders.
- Access Control Management
- Implement and maintain security administration and access policies using RACF, ACF2, or Top Secret.
- Enforce least privilege and role‑based access control (RBAC).
- Ensure multi‑factor authentication for privileged users.
- Ensure that privileged access and encryption policies are enforced.
- Compliance & Auditing
- Align security administration and access controls with regulatory frameworks (SOX, UCAL and PWC applications).
- Maintain detailed logs and audit trails for all access request and administrator provisioning activities.
- Utilize tools such as Vanguard Resource Administrator (VRA) for forensic analysis and Report Analyzer for reporting.
- Security Governance
- Monitor for unauthorized access and potential data leakage.
- Conduct regular access reviews and security assessments.
- Integrate with Identity and Access Management (IAM) systems for centralized governance.
- Team Management
- Lead and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).